Microsoft has expanded its bug bounty programme to include open-source projects and rewarded researchers with a record US$20 million, reinforcing security across its software supply chain.
Microsoft has expanded its bug bounty programme to include vulnerabilities in open-source projects, third-party components, and additional cloud services, while awarding a record US$20 million to security researchers during its latest programme year from July 1, 2025, to June 30, 2026.
The broader scope produced more than 300 vulnerability reports that would not have qualified under previous programme rules, with Microsoft paying over US$800,000 for findings related to the newly covered open-source and third-party software. The company said the move reflects the growing reliance of modern products on open-source software, external libraries, and interconnected cloud services, where vulnerabilities in upstream components can affect multiple Microsoft products.
A total of 562 researchers received rewards, averaging approximately US$35,000 each, while the overall payout increased by about US$3 million compared to the previous programme year.
Microsoft Zero Day Quest also contributed significantly, generating nearly 700 vulnerability reports and paying US$2.3 million to researchers from 20 countries.
The company said AI-assisted vulnerability research is accelerating the discovery of software flaws by helping researchers analyse code and identify weaknesses more quickly. However, it also acknowledged that processing the growing volume of AI-generated submissions has become increasingly challenging. Microsoft noted that AI systems such as Claude Mythos can identify vulnerabilities faster than developers can investigate and patch them.
Microsoft added that it recently shortened NuGet API key lifetimes to reduce software supply chain risks from stolen publishing credentials, complementing its broader effort to strengthen open-source ecosystem security.


